Back to Feed
PolicySep 8, 2026

Garante per la protezione dei dati personali (Italy) - 551/2026

Italian DPA fines Bologna University Hospital €10,000 for unlawful personal data publication.

Summary

The Italian Data Protection Authority (Garante) fined Bologna University Hospital IRCCS €10,000 for violating GDPR articles 5, 6, and 9. The hospital published personal data of ineligible candidates on its website for five years, which the DPA deemed unlawful as it could infer sensitive data and lacked a proper legal basis. The hospital has since removed the data and implemented preventative measures.

Full text

Help Garante per la protezione dei dati personali (Italy) - 551/2026: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 08:38, 8 September 2026 view sourceSf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators53 edits Tag: Decisions [1.0] Latest revision as of 08:40, 8 September 2026 view source Sf (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators53 editsmTag: Visual edit Line 98: Line 98: === Facts ====== Facts === A data subject complained to the DPA after their personal data was published on the website of the Bologna University Hospital IRCCS (the controller), and indexed on Google. The publication concerned the determination of eligibility or ineligibility of individuals participating in an income-based selection process. In the data subject’s case, the publication deemed them in ineligible.A data subject complained to the DPA after their personal data was published on the website of the Bologna University Hospital IRCCS (the controller), and indexed on Google. The publication concerned the determination of eligibility or ineligibility of individuals participating in an income-based selection process. In the data subject’s case, the publication deemed them in ineligible. The DPA initiated an investigation and found that the publication was part of the recruitment procedure used in the public sector, within which personnel are hired from employment centres into civil service. The selection process was not a competitive examination assessing the qualifications or professional experience of the individuals, but rather designed to assess the suitability regarding certain duties without comparative evaluation. The initiation of these procedures, and the results being published for a period of 5 years was undertaken and mandatory pursuant to national law.The DPA initiated an investigation and found that the publication was part of the recruitment procedure used in the public sector, within which personnel are hired from employment centres into civil service. The selection process was not a competitive examination assessing the qualifications or professional experience of the individuals, but rather designed to assess the suitability regarding certain duties without comparative evaluation. The initiation of these procedures, and the results being published for a period of 5 years was undertaken and mandatory pursuant to national law. Pursuant to the investigation, the DPA informed the controller that their processing operations were in violation of Articles 5, 6 and 9 GDPR, particularly that the selection process could associate the data subjects with a general condition of disability, potentially revealing sensitive personal data.Pursuant to the investigation, the DPA informed the controller that their processing operations were in violation of Articles 5, 6 and 9 GDPR, particularly that the selection process could associate the data subjects with a general condition of disability, potentially revealing sensitive personal data. The controller emphasised that the eligibility requirements allowed individuals who did not have a disability or face any financial hardship to participate, and that the selection results were published pursuant to national law, which required the publication of competitive examinations. However, in response to the DPA’s notice, the controller deleted the ranking list containing the personal data of the individuals who passed the selection procedure.The controller emphasised that the eligibility requirements allowed individuals who did not have a disability or face any financial hardship to participate, and that the selection results were published pursuant to national law, which required the publication of competitive examinations. However, in response to the DPA’s notice, the controller deleted the ranking list containing the personal data of the individuals who passed the selection procedure. The controller further clarified that the data processed did not fall within the special category nature of [[Article 9 GDPR|Article 9 GDPR]], claiming that it did not indicate any sensitive data about the data subject and other participants. Finally, the controller stated that they have taken measures to prevent such unlawful processing from happening again.The controller further clarified that the data processed did not fall within the special category nature of [[Article 9 GDPR]], claiming that it did not indicate any sensitive data about the data subject and other participants. Finally, the controller stated that they have taken measures to prevent such unlawful processing from happening again. === Holding === The DPA held that the controller’s reference to national law was irrelevant given the fact that the requirement does not apply to the publishing of ineligible candidates carried out through the placement of individuals registered on employment lists. The DPA clarified that this law applies to the final rankings of the eligible candidates who were not selected as part of a competitive selection procedure, which was not the case. Therefore, the DPA held that the controller did not identify a sufficient legal basis which allowed for this publication on its institutional website, let alone for five years. The DPA further held that the controller could have implemented measures to anonymise the personal data present on the ranking lists. The DPA found that the mere fact that participating in such a procedure could lead to inference of special category data which may have adverse effects on the data subject, makes the publication of such unlawful in light of [[Article 9 GDPR]]. === Holding ===The DPA imposed a €10.000 fine on the controller for publishing the personal data of 90 individuals in violation of [[Article 5 GDPR]], [[Article 6 GDPR]] and [[Article 9 GDPR]]. The DPA held that the controller’s reference to national law was irrelevant given the fact that the requirement does not apply to the publishing of ineligible candidates carried out through the placement of individuals registered on employment lists. The DPA clarified that this law applies to the final rankings of the eligible candidates who were not selected as part of a competitive selection procedure, which was not the case. Therefore, the DPA held that the controller did not identify a sufficient legal basis which allowed for this publication on its institutional website, let alone for five years. The DPA further held that the controller could have implemented measures to anonymise the personal data present on the ranking lists. The DPA found that the mere fact that participating in such a procedure could lead to inference of special category data which may have adverse effects on the data subject, makes the publication of such unlawful in light of [[Article 9 GDPR|Article 9 GDPR]]. The DPA imposed a €10.000 fine on the controller for publishing the personal data of 90 individuals in violation of [[Article 5 GDPR|Article 5 GDPR]], [[Article 6 GDPR|Article 6 GDPR]] and [[Article 9 GDPR|Article 9 GDPR]]. == Comment ==== Comment == Latest revision as of 08:40, 8 September 2026 Garante per la protezione dei dati personali - 551/2026 Authority: Garante per la protezione dei dati personali (Italy) Jurisdiction: Italy Relevant Law: Article 5 GDPR Article 6 GDPR Article 9 GDPR Type: Complaint Outcome: n/a Started: Decided: Published: Fine: 10000.0 EUR Parties: Bologna University Hospital IRCCS National Case Number/Name: 551/2026 European Case Law Identifier: n/a Appeal: n/a Original Language(s): Italian Original Source: Garante per la protezione dei dati personali (in IT) Initial Contributor: sf The DPA found the Bologna University Hospital IRCCS in violation of Articles 5, 6, and 9 GDPR for disclosing the personal data of the data subject’s and 95 other individuals on their institutional website. Contents 1 English Summary 1.1 Facts 1.2 Ho

Entities

Google (vendor)Bologna University Hospital IRCCS (product)